This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hjl Help...desperate

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Pamela.

If your friend hasn't got any disks and there's nothing in the manufacturer's documentation about a restore partition, I think that it would be best forget about formatting and re-installing Windows. Please let me know what you think about this. The latest HijackThis log is clean. We'll do another couple of checks to make sure that we've got everything.

Doing a System Restore should not result in losing any photographs. All of those sort of files should be unaffected.

———————————————————————–

F-Secure BlackLight

Please download F-Secure Blacklight (blbeta.exe) from here.
  • Click I ACCEPT and download the graphical user interface version to your Desktop
  • Double click the file to run it, choose I accept the agreement then click Scan
  • It will create a log on your desktop (fsbl-date/time.log).
  • If it finds anything, do not rename any. Legitimate items can also be present.
  • Exit Blacklight
Please post the contents of the log as a reply to this thread.

———————————————————————–

Kaspersky Online Scanner

Using Internet Explorer, go to: http://www.kaspersky.com/virusscanner
  • Click on Kaspersky Online Scanner
  • Click the Accept button
  • Follow the prompts to download and install the ActiveX component(s) and other software
    • If a yellow information bar appears at the top of the browser window, click on it and select Install ActiveX Control
    • If a message box appears, click on OK or Run as appropriate
  • Click Accept again (see the note below if using IE7)
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click 'Next'.
  • Now click on 'Scan Settings'
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
    • Scan Options: 'Scan Archives' and 'Scan Mail Bases'
  • Click 'OK'
  • Now under 'Select a target to scan' select 'My Computer'
  • The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
  • Now click on the Save as… button:
  • Save the report to your desktop (Save as type: Text document (txt))
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

——————————————————————–

Please post, as a reply to this thread:
  • The Blacklight report
  • The Kaspersky report
  • A new HijackThis log
Good morning Pamela. It's been a day or two since I posted. Are you having trouble with running the scans? I'm sorry to chase you up on this, but I go on holiday at the end of the week and we need to get moving if we are to get this finished. I go on Friday morning (UK time) and won't be back until the end of the month.
beynac, I am also leaving Friday…for the coast..Have run all scans but hijackthis…doing so now…taking forever with all programs running….will post shortly.
Finished Logs…I checked with my friend and she never made back-up discs nor has she done any updates. She has done one or two "sytem restores" as well. I believe I would like to make backup discs for her when we are finished and also get her startup faster and remove any games/garbage from her computer as she does not use them. She has notified banks and credit card companies of possible identity theft, as well. I am certain there are too many security/virus programs downloads….photo programs?…several of the programs she has downloaded came from discs "hacker friends" gave to her (not very good friends as she was not informed of the importance of backup discs and updates) we have discussed this and most probably will again …open to any and all suggestions.


Logfile of HijackThis v1.99.1
Scan saved at 5:17:42 AM, on 4/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Documents and Settings\Owner\Desktop\Daily virus protect\Pamela Daily Virus Protect\AVG Anti-Spyware 7.5\guard.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\safe-share\SafeShare.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PeoplePC\ISP6300\Browser\Bartshel.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\PeoplePC\ISP6300\Browser\PPShared.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\unzipped\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\3ca8c39b9b899185c2c09c220865d1ed\update\update.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/websearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP6300\BIN\PPCOLink.exe -STATION
O4 - HKLM\..\Run: [Unshare] C:\Program Files\safe-share\SafeShare.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1174994560826
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1175910867247
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\Owner\Desktop\Daily virus protect\Pamela Daily Virus Protect\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - C:\CFusionMX\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\CFusionMX\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\CFusionMX\db\slserver52\bin\swstrtr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe


Blacklight
04/09/07 18:58:03 [Info]: BlackLight Engine 1.0.61 initialized
04/09/07 18:58:03 [Info]: OS: 5.1 build 2600 (Service Pack 1)
04/09/07 18:58:04 [Note]: 7019 4
04/09/07 18:58:04 [Note]: 7005 0
04/09/07 18:58:09 [Note]: 7006 0
04/09/07 18:58:09 [Note]: 7011 1116
04/09/07 18:58:09 [Note]: 7026 0
04/09/07 18:58:10 [Note]: 7026 0
04/09/07 18:58:28 [Note]: FSRAW library version 1.7.1021
04/09/07 19:05:14 [Note]: 7007 0


Kaspersky
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, April 09, 2007 10:02:07 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 10/04/2007
Kaspersky Anti-Virus database records: 293429
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 63125
Number of viruses found: 10
Number of infected objects: 41 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:02:05

Infected Object Name / Virus Name / Last Action
C:\CFusionMX\db\slserver52\tracing\ColdFusion MX ODBC Agent.trc Object is locked skipped
C:\CFusionMX\db\slserver52\tracing\ColdFusion MX ODBC Server.trc Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-04-09_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007040920070410\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_4d4.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\eied_s7.cab/eied_s7_c_95.exe Infected: Trojan-Downloader.Win32.Mediket.cv skipped
C:\eied_s7.cab CAB: infected - 1 skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\Program Files\Norton AntiVirus\Quarantine\20E3405D.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\20F73C47.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\234C161C.exe Infected: Backdoor.Win32.Rbot.bjp skipped
C:\Program Files\Norton AntiVirus\Quarantine\234F4019.exe Infected: Backdoor.Win32.Rbot.bjp skipped
C:\Program Files\Norton AntiVirus\Quarantine\2C952D35.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\2CAB531C.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\2CE55B0C Infected: Trojan-Downloader.Win32.Mediket.cv skipped
C:\Program Files\Norton AntiVirus\Quarantine\2DA36979.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\2DAD676E.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\2DC051CB.exe Infected: Backdoor.Win32.Rbot.bjp skipped
C:\Program Files\Norton AntiVirus\Quarantine\2DD777B2.exe Infected: Backdoor.Win32.Rbot.bjp skipped
C:\Program Files\Norton AntiVirus\Quarantine\2DDA21AF.exe Infected: Backdoor.Win32.Rbot.bjp skipped
C:\Program Files\Norton AntiVirus\Quarantine\2DDD4BAB.exe Infected: Backdoor.Win32.Rbot.bjp skipped
C:\Program Files\Norton AntiVirus\Quarantine\2E5F7216.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\2E7200CB.tmp Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\2E7941FA.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\33415580 Infected: Trojan-Downloader.Win32.Mediket.cv skipped
C:\Program Files\Norton AntiVirus\Quarantine\36915713.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\36B524EB.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\3C522F50.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\3C62013E.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\3D110B5A.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\41B53E3E.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\432646A8.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\4CD21804.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\4CE269F2.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\58EA22DF Infected: Trojan-Downloader.Win32.Mediket.cv skipped
C:\Program Files\Norton AntiVirus\Quarantine\5D7962F7.exe Infected: Backdoor.Win32.SdBot.xd skipped
C:\Program Files\Norton AntiVirus\Quarantine\5D975CD7.tmp Infected: Trojan.Win32.Zapchast.cg skipped
C:\Program Files\Norton AntiVirus\Quarantine\62D45AA8.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\62E42C96.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\79193DDD.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\791C67DA.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\Norton AntiVirus\Quarantine\791F11D6.exe Infected: Trojan-Dropper.Win32.Agent.bah skipped
C:\Program Files\PeoplePC Accelerated\logs\output_Owner.log Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\benchmark.dat Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\49\d949 Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\57\6457 Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\7c\4e7c Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\activeDomains Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\c8\76c8 Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\ef\a0ef Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\codescache\nonactiveDomains Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\http_cache\HEADERS\_0000_1 Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\http_cache\HEADERS\_0000_2 Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\http_cache\_0000_1 Object is locked skipped
C:\Program Files\PeoplePC Accelerated\TEMP\http_cache\_0000_2 Object is locked skipped
C:\System Volume Information\_restore{593172EE-14D9-4262-8426-24BF2115D284}\RP306\A0040429.exe Infected: Backdoor.Win32.IRCBot.aak skipped
C:\System Volume Information\_restore{593172EE-14D9-4262-8426-24BF2115D284}\RP336\A0045374.dll Infected: Trojan-Clicker.Win32.Agent.ac skipped
C:\System Volume Information\_restore{593172EE-14D9-4262-8426-24BF2115D284}\RP336\A0045375.exe Infected: Trojan.Win32.LipGame.ab skipped
C:\System Volume Information\_restore{593172EE-14D9-4262-8426-24BF2115D284}\RP336\A0045376.exe Infected: Trojan-Downloader.Win32.Mediket.df skipped
C:\System Volume Information\_restore{593172EE-14D9-4262-8426-24BF2115D284}\RP341\change.log Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Lucent Win Modem.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\3ca8c39b9b899185c2c09c220865d1ed\BIT10.tmp Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.
Hi Pamela.

Which coast are you heading for on Friday?

There's one thing in the Kaspersky report we need to get rid of. The rest are in System Restore, which we'll clear at the end, or in Norton's Quarantine. There are a couple of programs that I would recommend uninstalling. The programs are SafeShare and SpywareBegone. SafeShare is clean in itself but can come bundled with some nasties. If your friend uses it, I suggest we just disable it from running at startup. SpywareBegone was, at one time, categorised as a rogue product. It has now been removed from the list, but there are better ones out there.

————————————————————–

Uninstall Programs

Please go to Start -> Control Panel -> Add or Remove Programs and uninstall the following programs, if they are present. Don't worry if they're not there.

SafeShare - if your friend doesn't want to keep it.
SpywareBegone

Reboot the computer

————————————————————–

Disable SpywareGuard

This is a good program but can interfere with our 'fix'. Right-click the running icon of Spywareguard in the system tray to open the program. Then go to Menu > File and choose Exit. It will automatically restart at next boot.

————————————————————-

Run HijackThis and click Scan and then check (tick) the following, if present (don't worry if any are missing):

O4 - HKLM\..\Run: [Unshare] C:\Program Files\safe-share\SafeShare.exe
O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

Close down all programs, browsers and other open windows. Make sure that only the above items are checked and then click on Fix checked.

Reboot the computer.

————————————————————–

Delete Files/Folders

Click on Start then My Computer, find the following files and folders (highlighted in red) and delete them, if present. Don't worry if any are missing, but please let me know.
  • C:\eied_s7.cab CAB <– File only
  • C:\Program Files\safe-share\ <– Folder (but only if you uninstalled the program)
  • C:\freescan\ <– Folder
———————————————————-

Unwanted Programs

I need to see alist of the programs on the computer. Please open HijackThis
  • Click on the Open the Misc Tools section button
  • Click on Open Uninstall Manager…
  • Click on Save List… (towards the bottom right)
  • Save the text file to a convenient location
I'll have a look through this, and the startup items, and make some more recomendations when I next post.

———————————————————-

Please post, as a reply to this thread:
  • The HijackThis Uninstall List
  • A new HijackThis log
Please let me know how the computer is running now.
Beynac….ARGGG….Hate this computer(dialup)!!!…third attempt to send logs…thank goodness for vacations…headed to Venice Florida…sharks tooth capital of the world..beautiful & Serene…counting down the minutes!

spyware begone not in add/remove programs…left shareware…she uses it….

HiJackThis removed only Global StartUp(2)

Delete files/folders could not find items listed…left SafeShare

logs…

Logfile of HijackThis v1.99.1
Scan saved at 7:16:04 AM, on 4/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Documents and Settings\Owner\Desktop\Daily virus protect\Pamela Daily Virus Protect\AVG Anti-Spyware 7.5\guard.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\safe-share\SafeShare.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PeoplePC\ISP6300\Browser\Bartshel.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\PeoplePC\ISP6300\Browser\PPShared.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PeoplePC\ISP6300\Browser\Bartshel.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\PeoplePC Accelerated\PeoplePC.exe
C:\WINDOWS\System32\wuauclt.exe
C:\unzipped\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/websearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP6300\BIN\PPCOLink.exe -STATION
O4 - HKLM\..\Run: [Unshare] C:\Program Files\safe-share\SafeShare.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\PeoplePC Accelerated\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\PeoplePC Accelerated\pac-image.html
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1174994560826
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1175910867247
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CF043678-3448-4E93-936A-827D54B2EEAC}: NameServer = 209.244.0.3 209.244.0.4
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Documents and Settings\Owner\Desktop\Daily virus protect\Pamela Daily Virus Protect\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - C:\CFusionMX\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\CFusionMX\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\CFusionMX\db\slserver52\bin\swstrtr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

HijackThis Uninstall log
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Reader 7.0.9
Adobe® Photoshop® Album Starter Edition 3.0
Atomic Pop
AVG Anti-Spyware 7.5
BlasterBall Wild
CardRd81
ccCommon
CCScore
ColdFusion MX
CR2
DarkOrbit
Detto Migration Kit
Easy Internet Sign-up
Encyclopaedia Britannica CD Installer
ESSBrwr
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
ESSTUTOR
ESSvpaht
ESSvpot
GemMaster
Google Desktop
Google Earth
Google Pack Screensaver
Google Toolbar for Firefox
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
HijackThis 1.99.1
HLPIndex
HLPPDOCK
HLPRFO
hp center
hp deskjet 656c series (Remove only)
HP Instant Support
HP Photo Printing Software
HP RecordNow
Inactive HP Printer Drivers (Remove only)
Inactive HP ScanJet Drivers (Remove only)
iTunes
Kaspersky Online Scanner
KazooStudio
KBD
Kodak EasyShare software
KSU
Lavasoft VX2 Cleaner
Lernout & Hauspie TruVoice American English TTS Engine
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Microsoft Money 2001
Microsoft Works 6.0
Microsoft Works and Money 2001 Setup Launcher
Mozilla Firefox (2.0.0.1)
MUSICMATCH Jukebox
My Photo Center
NCLEX-PN Exam Review
Norton AntiVirus 2005
Norton AntiVirus 2005 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton Spyware Scan provided by Yahoo!
Norton WMI Update
Notifier
NVIDIA Windows 2000/XP Display Drivers
OTtBP
OTtBPSDK
Panda ActiveScan
PeoplePC Online
PeoplePC:PeoplePal Toolbar 6.3
Picasa 2
PigPen
PS2
Python 1.5 combined Win32 extensions
Python 1.5.2 (final)
Quicken Financial Center
QuickTime
S3 Gamma
S3 Savage4 Family Display Switch2 Utility
SabreWing 2
Safe-Share
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB921883)
SFR
SHASTA
SKIN0001
SKINXSDK
SPBBC
Speedway
SpywareBlaster v3.5.1
SpywareGuard v2.2
Symantec
Symantec Script Blocking Installer
SymNet
Tcl 8.0.5 for Windows
Trend Micro System Cleaner v803
Update for Windows XP (KB898461)
VPRINTOL
War Games Virtual Warfare Demo
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix (SP2) [See Q329048 for more information]
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329441
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q815021
Windows XP Hotfix (SP2) Q817606
WinZip
WIRELESS
Yahoo! Messenger
Yahoo! Toolbar for Internet Explorer
ZIP PASSWORD FINDER

headed to Venice Florida…sharks tooth capital of the world..beautiful & Serene

It sounds wonderful! Have a good time. :)

I'm a bit worried that you couldn't find and delete this file: C:\eied_s7.cab. Let's make sure that we can see all files:

Show hidden System Files:
  • Click Start
  • Open My Computer
  • Select the Tools menu and click Folder Options
  • Select the View tab
  • Advanced Settings:
    • Under Hidden files and folders, select Show hidden files and folders
    • Uncheck Hide extensions for known file types
    • Uncheck Hide protected operating system files (Recommended)
  • Click Apply to All Folders
  • Click Yes to confirm
  • Click OK
———————————————————

Please try to manually delete the file again. If you cannot find it, or can find but not delete it, then please do the following.

Run HijackThis and click on Open the Misc Tools section.
Click on Delete a file on reboot…
Copy and paste the following into the "File name:" text box and then click Open:

C:\eied_s7.cab

When you are asked "Do you want to restart your computer now?", click OK.

Your PC MUST reboot to delete the file!

———————————————————–

I've looked through the uninstall list. There are a few programs that could be uninstalled, but if they're not running then they're not doing any harm. There's nothing that I recognise as being bad. The startup items are all either needed or are not going to slow the computer much. I suggest that your friend looks through the programs and gets rid of any that she definitely doesn't want. Make sure that you are sure what the program does before uninstalling it.

——————————————————–

Hate this computer!!!…third attempt to send logs.

What exactly is happening, or not happening?

Please also let me know what happens with the file deletion.
Beynac, Did as instructed…Two things that cause start-up to crawl are kodak update and yahoo messenger. I need to remove them from start-up! She can always access them manually. Most of these postings I have done on my secure computer (DSL), much faster, hijackthis must be done on hers….I agree with what you said about her programs…I just need to work on startup programs…Thank you for your help….Shall I download SP2 now? The computer I am working on is on dial-up so each time I recieve a phone call and the person on the other end insists on allowing the phone to ring several times I am diconnected and reconnected…bumped offline and must start over…annoying thats all. I keep forgetting to block my call waiting so that callers recieve a busy signal. I am very hard of hearing and folks just worry when I don't pick up.
Hi Pamela.

Did you manage to get rid of that file?

If you want to remove Kodak Updater and Yahoo Messenger from startup, then fix the following HijackThis entries. Provided that the HijackThis folder is not deleted, you can always restore from the HijackThis backup (the Backup button is under Misc Tools).

Run HijackThis and click Scan and then check (tick) the following:

O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet


Close down all programs, browsers and other open windows. Make sure that only the above items are checked and then click on Fix checked.

————————————————————

There's a couple of things to tidy up. You can delete Blacklight, SDFix and their reports. I suggest that you keep ATF Cleaner and AVG Anti-Spyware as they are useful programs. We need to re-hide the system files.

Hide System Files:
  • Click Start
  • Open My Computer
  • Select the Tools menu and click Folder Options
  • Select the View tab
  • Advanced Settings:
    • Under Hidden files and folders, select Do not show hidden files and folders
    • Select Hide extensions for known file types
    • Select Hide protected operating system files (Recommended)
  • Click Apply to All Folders
  • Click Yes
  • Click OK
—————————————————–

Flush System Restore

Now that the computer is clean, we need to clear out the old, infected Restore Points.

Turn OFF System Restore.
  • Click on Start
  • Right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Check Turn off System Restore
  • Click Apply, and then click OK
Restart your computer

Turn ON System Restore.
  • Click on Start
  • Right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Uncheck Turn off System Restore
  • Click Apply, and then click OK
This will create a new, clean restore point.

——————————————————–

Windows XP - Service Pack 2

Yes, you can download SP2 now. You can download it, or order the CD, from here.

——————————————————–

Please let me know if you have any questions.
Beynac, Finished all listed above…downloading SP2 now…. One question….with all of the protections she has on her computer should symantec be the only one running all the time and run the others once a week? Could you advise on these programs and when/how they should run? Also…if you don't mind, where are you heading for holiday? Thanks Again for your outstanding help! Pamela P.S. If you had a brand new computer with LiveOne Care and Defender….What protections would you have? I was thinking of buying G Data Security AVK, or no, Symantec instead?
Hi Pamela.

Symantec/Norton program(s) give anti-virus real-time protection. I can't see that it includes a firewall. If not, please make sure that you activate the Windows firewall once you have installed SP2. Windows XP Firewall is better than nothing, but it only protects against incoming traffic. It doesn't protect you against outgoing baddies trying to "phone home". I strongly suggest that you use one of the third-party ones. Sunbelt Kerio and Zone Alarm are both good and have a free version. I cannot stress how important it is that you use a firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can greatly lower your risk. I suggest that you get SP2 installed first.

SpywareGuard gives real-time protection against spyware. AVG Anti-Spyware can also do this, if you pay for the full version. You shouldn't have both these programs running at the same time. I suggest that you keep SpywareGuard running and just use AVG (free version) for regular scans (don't bother running scans in safe mode unless you think there is an infection).

Ad-Aware SE Personal doesn't run in real-time. Update it and run a scan every week or two.

Kaspersky Online Scanner and Panda ActiveScan can be uninstalled. They are online scanners and it's best to download them afresh if you need them.

SpywareBlaster: This program will:
  • Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
  • Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
  • Restrict the actions of potentially unwanted sites in Internet Explorer.
This program blocks these items but does not run in the background. It therefore does not use any resources.

Norton Spyware Scan provided by Yahoo!: I have no knowledge of this program, so cannot advise you whether to keep or uninstall it.

I recommend that you have a look at Firetrust SiteHound. This gives warnings when you are about to enter a website that is on their 'block' list. An alternative is McAfee SiteAdvisor. I use SiteHound, but both have a good reputation (N.B. use only one of them, not both).

Overall, I don't think that the protection is 'over the top'. The main thing is to make sure that everything is kept up-to-date.

—————————————————————-

where are you heading for holiday?

My wife and I are going to spend a couple of days with our family in Sussex and then we're going to the New Forest for a week. This is a lovely area of forest and heathland between Southampton and Bournemouth - lots of good walks and country pubs. :D We are then going to have a look round Cambridge on the way home. We're really looking forward to it - especially seeing the grandchildren!
Beynac, Thank you for all of the advise…and straightening out all of this mess on my friends computer. I hope you and your wife enjoy your holiday…and the grandchildren too! We can hardly wait for our own. Gratefully, Pamela
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI